<?php
namespace App\Security;
use Symfony\Component\HttpFoundation\JsonResponse;
use Symfony\Component\HttpFoundation\Request;
use Symfony\Component\HttpFoundation\Response;
use Symfony\Component\Security\Core\Authentication\Token\TokenInterface;
use Symfony\Component\Security\Core\Exception\AuthenticationException;
use Symfony\Component\Security\Core\Exception\CustomUserMessageAuthenticationException;
use Symfony\Component\Security\Http\Authenticator\AbstractAuthenticator;
use Symfony\Component\Security\Http\Authenticator\Passport\Badge\UserBadge;
use Symfony\Component\Security\Http\Authenticator\Passport\Passport;
use Symfony\Component\Security\Http\Authenticator\Passport\SelfValidatingPassport;
use App\Entity\Admin;
use Doctrine\ORM\EntityManagerInterface;
use Symfony\Component\Security\Http\Authenticator\Passport\Credentials\CustomCredentials;
use Symfony\Component\Security\Core\User\UserInterface;
use Symfony\Component\HttpFoundation\RedirectResponse;
use Symfony\Component\Routing\RouterInterface;
use Symfony\Component\Security\Core\Authorization\AuthorizationCheckerInterface;
use Symfony\Component\Security\Core\Security;
/**
* 使用这个验证访问权限 暂时无法使用rememberme功能(可改造)
*/
class ApiAdminAuthenticator extends AbstractAuthenticator
{
public function __construct(
protected EntityManagerInterface $entityManager,
protected Security $security,
protected AuthorizationCheckerInterface $authChecker,
protected RouterInterface $router,
) {}
/**
* Called on every request to decide if this authenticator should be
* used for the request. Returning `false` will cause this authenticator
* to be skipped.
*/
public function supports(Request $request): ?bool
{
return 0 === strpos($request->attributes->get('_route'), 'admin_auth');
}
public function authenticate(Request $request): Passport
{
$admin = $this->security->getUser();
if (!$admin) throw new CustomUserMessageAuthenticationException('请重新登陆系统123', ['code'=>-1]);
////此处验证api是否用访问权限
$router = $request->attributes->get('_route');
$isAuth = $this->authChecker->isGranted($router);
if(!$isAuth && $admin->getUsername() !== 'admin') throw new CustomUserMessageAuthenticationException('没有访问权限', ['code'=>1]);
return new SelfValidatingPassport(new UserBadge($admin->getUsername()));
}
public function onAuthenticationSuccess(Request $request, TokenInterface $token, string $firewallName): ?Response
{
// on success, let the request continue
return null;
}
public function onAuthenticationFailure(Request $request, AuthenticationException $exception): ?Response
{
if ($request->isXmlHttpRequest()) {
$data = [
// you may want to customize or obfuscate the message first
'code' => $exception->getMessageData()['code'] ?? -1,
'message' => strtr($exception->getMessageKey(), $exception->getMessageData())
];
return new JsonResponse($data, Response::HTTP_UNAUTHORIZED);
}
$request->getSession()->getFlashBag()->add('alert', strtr($exception->getMessageKey(), $exception->getMessageData()));
if ($exception->getMessageData()['code'] === -1) return new RedirectResponse($this->router->generate('admin.login'));
throw new \Exception(strtr($exception->getMessageKey(), $exception->getMessageData()));
}
}